Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2025-10637 The Social Feed Gallery plugin for WordPress is vulnerable to Information Exposure in versions less than, or equal to, 4.9.2. This is due to the plug… Mitigation only Fix from $1,6002025-10-25 MEDIUM 5.3 CVE-2025-11269 The Product Filter by WBW plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'approveNo… Patch available Fix from $1,6002025-10-25 MEDIUM 5.3 CVE-2025-11564 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… Tutor Lms 3.9.0+ Fix from $1,6002025-10-25 MEDIUM 5.3 CVE-2025-10694 The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to unauthorized access of… Mitigation only Fix from $1,6002025-10-25 MEDIUM 5.3 CVE-2025-10579 The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … Mitigation only Fix from $1,6002025-10-25 HIGH 8.7 CVE-2025-62714 Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project. Prior to version 0.2.0, ther… Patch available Fix from $1,9502025-10-24 MEDIUM 5.3 CVE-2025-12134 The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for WordPress is vulnerable to unau… Mitigation only Fix from $1,6002025-10-24 HIGH 8.8 CVE-2025-36361 IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actio… App Connect Enterprise after 13.0.4.2 Fix from $1,9502025-10-24 MEDIUM 5.4 CVE-2025-10749 The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in all versions up to, and incl… Mitigation only Fix from $1,6002025-10-24 MEDIUM 5.3 CVE-2025-62256 Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA th… Digital Experience Platform 7.4.3.110+ Fix from $1,6002025-10-23 HIGH 8.7 CVE-2025-62614 BookLore is a self-hosted web app for organizing and managing personal book collections. In versions 1.8.1 and prior, an authentication bypass vulner… Patch available Fix from $1,9502025-10-22 MEDIUM 6.5 CVE-2025-62247 Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 20… Digital Experience Platform 2024.q1.20+ Fix from $1,6002025-10-22 MEDIUM 5.4 CVE-2025-62027 Missing Authorization vulnerability in StellarWP Event Tickets event-tickets.This issue affects Event Tickets: from n/a through <= 5.26.3. Mitigation only Fix from $1,6002025-10-22 MEDIUM 5.4 CVE-2025-62048 Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform SmartCrawl smartcrawl-seo.This issue affects SmartCrawl: from n/… Mitigation only Fix from $1,6002025-10-22 MEDIUM 6.5 CVE-2025-62019 Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor recipe-card-blocks-by-wpzoom.This issue affects Recipe Car… Mitigation only Fix from $1,6002025-10-22 HIGH 7.5 CVE-2025-62022 Missing Authorization vulnerability in BuddyPress BuddyPress buddypress.This issue affects BuddyPress: from n/a through <= 14.3.4. Mitigation only Fix from $1,9502025-10-22 MEDIUM 5.4 CVE-2025-62006 Missing Authorization vulnerability in VeronaLabs WP SMS wp-sms.This issue affects WP SMS: from n/a through <= 7.0.1. Mitigation only Fix from $1,6002025-10-22 MEDIUM 6.5 CVE-2025-53424 Missing Authorization vulnerability in vanquish WooCommerce Orders & Customers Exporter woocommerce-orders-ei allows Exploiting Incorrectly Configure… Mitigation only Fix from $1,6002025-10-22 MEDIUM 6.5 CVE-2025-53421 Missing Authorization vulnerability in PickPlugins Accordion accordions allows Exploiting Incorrectly Configured Access Control Security Levels.This … Mitigation only Fix from $1,6002025-10-22 MEDIUM 6.3 CVE-2025-53236 Missing Authorization vulnerability in AndonDesign UDesign Core u-design-core allows Exploiting Incorrectly Configured Access Control Security Levels… Mitigation only Fix from $1,6002025-10-22 MEDIUM 6.5 CVE-2025-52757 Missing Authorization vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Exploiting Incorrectly Configured Acc… Mitigation only Fix from $1,6002025-10-22 MEDIUM 6.5 CVE-2025-52738 Missing Authorization vulnerability in Wikimedia Foundation Wikipedia Preview wikipedia-preview allows Exploiting Incorrectly Configured Access Contr… Mitigation only Fix from $1,6002025-10-22 MEDIUM 6.5 CVE-2025-49961 Missing Authorization vulnerability in Breeze Team Breeze Checkout breeze-checkout allows Exploiting Incorrectly Configured Access Control Security L… Mitigation only Fix from $1,6002025-10-22 MEDIUM 5.4 CVE-2025-49949 Missing Authorization vulnerability in templazee Templazee templazee allows Exploiting Incorrectly Configured Access Control Security Levels.This iss… Mitigation only Fix from $1,6002025-10-22 HIGH 7.2 CVE-2025-49950 Missing Authorization vulnerability in billingo Official Integration for Billingo billingo allows Privilege Escalation.This issue affects Official In… Mitigation only Fix from $1,9502025-10-22 HIGH 7.5 CVE-2025-49925 Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affec… Wordpress Learning Management System 1.9.9.8+ Fix from $1,9502025-10-22 MEDIUM 5.3 CVE-2025-49913 Missing Authorization vulnerability in CoSchedule CoSchedule coschedule-by-todaymade allows Exploiting Incorrectly Configured Access Control Security… No fix yet Fix from $1,6002025-10-22 HIGH 8.6 CVE-2025-49916 Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Accessing Functionality Not Properly Constrained … Mitigation only Fix from $1,9502025-10-22 MEDIUM 5.4 CVE-2025-49920 Missing Authorization vulnerability in accessiBe Web Accessibility By accessiBe accessibe allows Exploiting Incorrectly Configured Access Control Sec… No fix yet Fix from $1,6002025-10-22 MEDIUM 5.3 CVE-2025-49899 Missing Authorization vulnerability in jjlemstra Whydonate wp-whydonate allows Accessing Functionality Not Properly Constrained by ACLs.This issue af… Mitigation only Fix from $1,6002025-10-22